Choosing an MSP? Five Questions To Ask

For many small and medium-sized businesses, outsourcing IT support makes perfect sense. Internal resources are stretched, cyber threats continue to increase, and having access to specialist expertise can be far more cost-effective than building an in-house team. But not all Managed Service Providers (MSPs) are created equal.

The National Cyber Security Centre (NCSC) recently published guidance to help SMEs select and work effectively with MSPs, highlighting the importance of security, transparency and clear accountability when choosing a provider. So, what should business owners be looking for?

Don’t Just Ask What They Do – Ask How They Do It

The NCSC recommends looking for recognised security accreditations such as Cyber Essentials Plus and ISO 27001. While certifications aren’t the whole story, they provide evidence that security is being taken seriously and that processes are in place to protect customer data and systems. Equally important is understanding how services are configured, monitored and maintained once they’re in place. Security isn’t just about buying the right tools – it’s about using them correctly.

Look Beyond the Sales Pitch

Case studies, testimonials and customer references can tell you far more than a polished presentation. The NCSC encourages organisations to speak to existing clients, particularly businesses of a similar size and complexity. A provider’s track record often reveals how responsive they are, how well they communicate and how effectively they handle issues when things don’t go to plan.

Make Security Responsibilities Crystal Clear

One of the biggest risks in any managed service arrangement is ambiguity. Business owners often assume their provider is taking care of everything, while the MSP assumes the customer is responsible for certain areas. The result can be dangerous gaps in protection. The NCSC advises ensuring contracts clearly define roles, responsibilities, incident reporting procedures and liability arrangements. If a cyber incident occurs, everyone should know exactly who is responsible for what.

Ask Tough Questions About Cyber Security

A reliable MSP should be comfortable discussing:

  • How quickly security patches are applied
  • Backup and recovery arrangements
  • Multi-factor authentication (2FA/MFA)
  • Security monitoring and logging
  • Incident response processes
  • Access controls and privileged accounts

The NCSC specifically highlights patching, backups, access management, logging and incident response as key areas SMEs should discuss before signing any contract. If your provider struggles to answer these questions clearly, consider it a warning sign.

Think About What Happens When Things Go Wrong

Nobody likes to dwell on worst-case scenarios, but resilience is often what separates good providers from great ones. How quickly will they respond to a critical incident? How will they communicate with you? What happens if they experience a cyber attack themselves? The NCSC recommends agreeing service levels, notification procedures, reporting requirements and recovery expectations upfront. SMEs should also ensure there is a clear exit strategy and defined responsibilities for managing end-of-life systems and technology.

“One of the most common misconceptions we see is that cyber security becomes someone else’s problem once you’ve outsourced IT. A good MSP should strengthen your security, but the strongest outcomes come from partnership. Both parties need a clear understanding of their responsibilities and regular conversations about risk, resilience and business priorities.” Andrew Spencer, Senior Security Consultant

Practical Advice for SMBs

Before selecting or renewing an MSP contract, take an hour to review these five questions:

  1. Do they hold recognised security certifications?
  2. Can they provide relevant customer references?
  3. Are responsibilities clearly documented?
  4. Can they explain their security processes in plain English?
  5. Do your service levels and reporting requirements reflect your business needs?

If the answer to any of these questions is uncertain, it’s worth taking a closer look.

The Bottom Line

An MSP can become one of your most trusted business partners, helping your organisation stay productive, secure and resilient. But choosing the right provider requires more than comparing costs and service packages. As the NCSC guidance makes clear, successful MSP relationships are built on transparency, accountability and a shared commitment to cyber security. Investing a little more time upfront could save your business a great deal of disruption later.

At Evolve North, we help organisations strengthen their cyber security through practical, proportionate support tailored to the needs of SMBs. Whether you’re reviewing an existing provider, developing your cyber security strategy, working towards Cyber Essentials, improving cyber resilience or identifying security weaknesses before they become a problem, we provide clear, actionable advice without unnecessary complexity.

If you’d like an independent conversation about your current approach to cyber security, or whether your MSP is delivering the level of assurance your business needs, contact us at info@evolvenorth.com or call 01748 905 002.

Arrange a FREE Consultation

Want to learn more about improving your organisation's security? Our team is here to answer your questions and explain the options available. In a free consultation, we'll help you understand the services we offer and how they can support your goals. It's a simple, no-obligation way to start exploring the right approach for your business.